<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by author Oliver Hader</description>
        <language>en</language>
        <link>https://news.typo3.com/article/author/oliver-hader/blog.author.xml</link>
        <lastBuildDate>Mon, 07 Sep 2026 11:40:07 +0200</lastBuildDate>
        
    
    
        
<item><title>TYPO3 14.3.6 and 13.4.34 security releases published</title><link>https://news.typo3.com/article/typo3-1436-and-13434-security-releases-published</link><comments>https://news.typo3.com/article/typo3-1436-and-13434-security-releases-published#comments</comments><pubDate>Tue, 11 Aug 2026 09:35:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1436-and-13434-security-releases-published</guid><description>The versions 14.3.6 and 13.4.34 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="251750"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/7/e/csm_Security_Release_listing_1400x933_LAY01_2fec4ea8a8.webp" /></item>


    
        
<item><title>TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-021</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-021#comments</comments><pubDate>Tue, 11 Aug 2026 09:30:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-021</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3 14.3.5 and 13.4.33 security releases published</title><link>https://news.typo3.com/article/typo3-1435-and-13433-security-releases-published</link><comments>https://news.typo3.com/article/typo3-1435-and-13433-security-releases-published#comments</comments><pubDate>Tue, 14 Jul 2026 14:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1435-and-13433-security-releases-published</guid><description>The versions 14.3.5 and 13.4.33 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="251750"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/7/e/csm_Security_Release_listing_1400x933_LAY01_2fec4ea8a8.webp" /></item>


    
        
<item><title>TYPO3-CORE-SA-2026-020: Unrestricted File Upload in Form Framework</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-020</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-020#comments</comments><pubDate>Tue, 14 Jul 2026 12:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-020</guid><description>It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.</description></item>


    
        
<item><title>TYPO3 14.3.3 and 13.4.31 security releases published</title><link>https://news.typo3.com/article/typo3-1433-and-13431-security-releases-published</link><comments>https://news.typo3.com/article/typo3-1433-and-13431-security-releases-published#comments</comments><pubDate>Tue, 09 Jun 2026 14:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1433-and-13431-security-releases-published</guid><description>The versions 14.3.3 and 13.4.31 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="251750"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/7/e/csm_Security_Release_listing_1400x933_LAY01_2fec4ea8a8.webp" /></item>


    
        
<item><title>TYPO3-CORE-SA-2026-019: Broken Access Control in Form Framework</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-019</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-019#comments</comments><pubDate>Tue, 09 Jun 2026 12:19:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-019</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-018: Insecure Deserialization in Core API</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-018</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-018#comments</comments><pubDate>Tue, 09 Jun 2026 12:18:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-018</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-017: Privilege Escalation &amp; SQL Injection in Form Framework</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-017</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-017#comments</comments><pubDate>Tue, 09 Jun 2026 12:17:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-017</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-016: Broken Access Control in File Abstraction Layer</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-016</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-016#comments</comments><pubDate>Tue, 09 Jun 2026 12:16:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-016</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-015: Broken Access Control in Backend API</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-015</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-015#comments</comments><pubDate>Tue, 09 Jun 2026 12:15:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-015</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-014: Broken Access Control in Clipboard</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-014</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-014#comments</comments><pubDate>Tue, 09 Jun 2026 12:14:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-014</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-013: Broken Access Control in Media Module</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-013</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-013#comments</comments><pubDate>Tue, 09 Jun 2026 12:13:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-013</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-012: Broken Access Control in DataHandler</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-012</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-012#comments</comments><pubDate>Tue, 09 Jun 2026 12:12:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-012</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-011: Broken Access Control in Recycler</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-011</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-011#comments</comments><pubDate>Tue, 09 Jun 2026 12:11:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-011</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-010: Cross-Site Scripting in Indexed Search</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-010</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-010#comments</comments><pubDate>Tue, 09 Jun 2026 12:10:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-010</guid><description>It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-009: Open Redirect in TYPO3 CMS</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-009</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-009#comments</comments><pubDate>Tue, 09 Jun 2026 12:09:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-009</guid><description>It has been discovered that TYPO3 CMS is susceptible to open redirect.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-008: Broken Access Control in Form Framework</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-008</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-008#comments</comments><pubDate>Tue, 09 Jun 2026 12:08:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-008</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-007: Broken Access Control in File Abstraction Layer</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-007</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-007#comments</comments><pubDate>Tue, 09 Jun 2026 12:07:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-007</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-006: By-passing Cross-Site Scripting Protection in HTML Sanitizer</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-006</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-006#comments</comments><pubDate>Tue, 09 Jun 2026 12:06:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-006</guid><description>It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.</description></item>


    
        
<item><title>TYPO3 14.3.2 and 13.4.30 maintenance releases published</title><link>https://news.typo3.com/article/typo3-1432-and-13430-maintenance-releases-published</link><comments>https://news.typo3.com/article/typo3-1432-and-13430-maintenance-releases-published#comments</comments><pubDate>Tue, 26 May 2026 12:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1432-and-13430-maintenance-releases-published</guid><description>The versions 14.3.2 and 13.4.30 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="252528"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_537898bf9f.webp" /></item>


    
        
<item><title>Changes to the TYPO3 Bug Bounty Program</title><link>https://news.typo3.com/article/changes-to-the-typo3-bug-bounty-program</link><comments>https://news.typo3.com/article/changes-to-the-typo3-bug-bounty-program#comments</comments><pubDate>Tue, 19 May 2026 09:38:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/changes-to-the-typo3-bug-bounty-program</guid><description>Extension security reporting continues — financial rewards for extension findings will end on 31 May 2026.</description><enclosure
            length="150907"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/e/9/csm_Security_Blocker_listing_1400x933_LAY02_52ad5327dd.webp" /></item>


    
        
<item><title>TYPO3 14.3.1 and 13.4.29 maintenance releases published</title><link>https://news.typo3.com/article/typo3-1431-and-13429-maintenance-releases-published</link><comments>https://news.typo3.com/article/typo3-1431-and-13429-maintenance-releases-published#comments</comments><pubDate>Tue, 12 May 2026 12:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1431-and-13429-maintenance-releases-published</guid><description>The versions 14.3.1 and 13.4.29 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="252528"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_537898bf9f.webp" /></item>


    
        
<item><title>TYPO3-CORE-SA-2026-005: Cleartext storage of Backend User Passwords</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-005</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-005#comments</comments><pubDate>Tue, 21 Apr 2026 11:05:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-005</guid><description>It has been discovered that TYPO3 CMS is susceptible to sensitive data exposure.</description></item>


    
        
<item><title>TYPO3 13.4.28 and 12.4.45 maintenance releases published</title><link>https://news.typo3.com/article/typo3-13428-and-12445-maintenance-releases-published</link><comments>https://news.typo3.com/article/typo3-13428-and-12445-maintenance-releases-published#comments</comments><pubDate>Tue, 14 Apr 2026 13:30:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-13428-and-12445-maintenance-releases-published</guid><description>The versions 13.4.28 and 12.4.45 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="252528"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_537898bf9f.webp" /></item>


    
        
<item><title>TYPO3 13.4.27 and 12.4.44 maintenance releases published</title><link>https://news.typo3.com/article/typo3-13427-and-12444-maintenance-releases-published</link><comments>https://news.typo3.com/article/typo3-13427-and-12444-maintenance-releases-published#comments</comments><pubDate>Tue, 10 Mar 2026 13:30:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-13427-and-12444-maintenance-releases-published</guid><description>The versions 13.4.27 and 12.4.44 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="252528"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_537898bf9f.webp" /></item>


    
        
<item><title>TYPO3 14.1.1, 13.4.26 and 12.4.43 maintenance releases published</title><link>https://news.typo3.com/article/typo3-1411-13426-and-12443-maintenance-releases-published</link><comments>https://news.typo3.com/article/typo3-1411-13426-and-12443-maintenance-releases-published#comments</comments><pubDate>Fri, 20 Feb 2026 10:30:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1411-13426-and-12443-maintenance-releases-published</guid><description>The versions 14.1.1, 13.4.26 and 12.4.43 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="252528"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_537898bf9f.webp" /></item>


    
        
<item><title>TYPO3 13.4.25 maintenance release published</title><link>https://news.typo3.com/article/typo3-13425-maintenance-release-published</link><comments>https://news.typo3.com/article/typo3-13425-maintenance-release-published#comments</comments><pubDate>Tue, 10 Feb 2026 11:00:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-13425-maintenance-release-published</guid><description>The version 13.4.25 of the TYPO3 Enterprise Content Management System has just been released.</description><enclosure
            length="252528"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_537898bf9f.webp" /></item>


    
        
<item><title>TYPO3 13.4.24 and 12.4.42 maintenance releases published</title><link>https://news.typo3.com/article/typo3-13424-and-12442-maintenance-releases-published</link><comments>https://news.typo3.com/article/typo3-13424-and-12442-maintenance-releases-published#comments</comments><pubDate>Tue, 20 Jan 2026 08:30:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-13424-and-12442-maintenance-releases-published</guid><description>The versions 13.4.24 and 12.4.42 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="252528"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_537898bf9f.webp" /></item>


    
        
<item><title>TYPO3 14.0.2, 13.4.23 and 12.4.41 security releases published</title><link>https://news.typo3.com/article/typo3-1402-13423-and-12441-security-releases-published</link><comments>https://news.typo3.com/article/typo3-1402-13423-and-12441-security-releases-published#comments</comments><pubDate>Tue, 13 Jan 2026 13:00:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1402-13423-and-12441-security-releases-published</guid><description>The versions 14.0.2, 13.4.23 and 12.4.41 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="251750"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/7/e/csm_Security_Release_listing_1400x933_LAY01_2fec4ea8a8.webp" /></item>


    
        
<item><title>TYPO3-CORE-SA-2026-004: Insecure Deserialization via Mailer File Spool</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-004</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-004#comments</comments><pubDate>Tue, 13 Jan 2026 12:04:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-004</guid><description>It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.</description></item>


    



    </channel>
</rss>
